DLP Policy Violation
Low
Resolved
ALR-00087 · 2026-05-23T07:20:44Z
Description
DLP policy violation: user 'system' attempted to email 3 files classified as 'Confidential' to external address from WS-MAC-005.
Alert Metadata
Endpoint Information
MITRE ATT&CK Mapping
Investigation Timeline
07:20:44
Event ingested by SOC365 Engine
07:20:45
EmilyAI triage started — correlation enrichment
07:20:59
EmilyAI confidence: 97% — escalated to human analyst
07:21:02
Alert assigned to analyst: EmilyAI (auto)
07:22:20
Investigation started — querying SIEM and threat intelligence
07:26:47
Containment action taken — endpoint isolated
07:39:11
Alert resolved — remediation complete
Related Alerts
| ID | Time | Alert | Severity | Status | Host |
|---|---|---|---|---|---|
| ALR-00106 | 2h ago | DLP Policy Violation | High | Investigating | WS-PC-004 |
| ALR-00124 | 4h ago | Ransomware Behaviour Detected | Low | Investigating | WS-MAC-005 |
| ALR-00165 | 10h ago | Credential Stuffing Attempt | Low | Open | WS-MAC-005 |
| ALR-00495 | 10h ago | DLP Policy Violation | Medium | Open | SRV-DC-01 |
| ALR-00369 | 17h ago | Anomalous DNS Query | Medium | Resolved | WS-MAC-005 |